background image

 

SIGNAMAX a.s.  
Office: Vlarska 22, 627 00 Brno, CZ  
T:+420 533 338 854 l F:+420 533 338 883 l www.signamax.eu

 

24 PORTS 10/100BASE-T MANAGEMENT 

ETHERNET SWITCH WITH 2 1000BASE-X 

COMBO SFP SLOTS UPLINK  

 

Model

:

 500-7624FE2GC

 

Summary of Contents for 500-7624FE2GC

Page 1: ...AX a s Office Vlarska 22 627 00 Brno CZ T 420 533 338 854 l F 420 533 338 883 l www signamax eu 0 24 PORTS 10 100BASE T MANAGEMENT ETHERNET SWITCH WITH 2 1000BASE X COMBO SFP SLOTS UPLINK Model 500 7624FE2GC ...

Page 2: ...his equipment does cause harmful interference to radio or television reception which can be determined by turning the equipment off and on the user is encouraged to try to correct the interference by one or more of the following measures Reorient or relocate the receiving antenna Increase the separation between the equipment and receiver Connect the equipment into a different outlet from that the ...

Page 3: ... 2 3 8 Login Username Password 23 2 4 User Mode 24 2 5 Enable Mode 24 2 5 1 Backup command mode 25 2 5 2 Console command mode 26 2 5 3 IP command mode 26 2 5 4 Ping command mode 27 2 5 5 Restore command mode 28 2 5 6 Service command mode 28 2 5 7 System command mode 31 2 5 8 Time server command mode 32 2 5 9 Upgrade command mode 33 2 5 10 User command mode 34 2 6 Configuration Mode 36 2 6 1 ACL co...

Page 4: ...ree 84 4 3 6 1 RSTP Switch Settings 85 4 3 6 2 RSTP Physical Port Settings 86 4 3 7 802 1X Configuration 87 4 3 7 1 802 1X System 88 4 3 7 2 802 1X Port Admin State 89 4 3 7 3 802 1X Port Reauthenticate 89 4 3 8 MAC Address Management 89 4 3 9 VLAN Configuration 90 4 3 9 1 802 1q Tag VLAN 91 4 3 9 2 802 1q Tag VLAN Member 93 4 3 9 3 802 1q Service VLAN Member 93 4 3 9 4 802 1q Protocol VLAN 94 4 3...

Page 5: ...tus 120 4 4 3 DHCP Snooping 120 4 4 4 MAC Address Table 121 4 4 5 Port Counters 121 4 4 5 1 Port Traffic Statistics 122 4 4 5 2 Port Packet Error Statistics 122 4 4 5 3 Port Packet Analysis Statistics 124 4 4 6 RSTP Monitor 125 4 4 6 1 RSTP VLAN Bridge Overview 125 4 4 6 2 RSTP Port Status 126 4 4 7 IGMP Monitor 127 4 4 7 1 IGMP Snooping Status 127 4 4 7 2 IGMP Group Table 128 4 4 8 SFP Informatio...

Page 6: ...bles users to configure and monitor the operational status both locally and remotely This User s Manual will explain how to use command line interface and Web Management to configure your Managed Switch The readers of this manual should have knowledge about their network typologies and about basic networking concepts so as to make the best of this user s manual and maximize the Managed Switch s pe...

Page 7: ...t System Standard SNMP based network management system provides users a way to manage the Managed switch through the network remotely When you use a SNMP based network management system the Managed switch becomes one of the managed devices network elements in that system The Managed Switch management module contains an SNMP agent that will respond to the requests from the SNMP based network manage...

Page 8: ... SX transceiver use the multi mode fiber cable that one side is male duplex LC connector type To connect to 1000Base LX transfer use the single mode fiber cable that one side is male duplex LC connector type 10 100Base T RJ 45 Auto MDI MDIX Port 24 x 10 100Base T RJ 45 Auto MDI MDIX ports are located at the front panel of the Managed Switch These RJ 45 ports enable users to connect their tradition...

Page 9: ...ment via Console port is activated In other words you have successfully entered a terminal emulation program and are ready to begin the management session Green The Managed Switch is operating normally Orange The Managed Switch is booting up Orange blinking Insert a pin or paper clip to push the Reset button for 3 seconds then the Managed Switch will restart The Status LED blinks in orange once St...

Page 10: ...SIGNAMAX a s Office Vlarska 22 627 00 Brno CZ T 420 533 338 854 l F 420 533 338 883 l www signamax eu 9 ...

Page 11: ... be reached by any other means You also need to use the Local Console Management to setup the Switch network configuration for the first time You can setup the IP address and change the default configuration to desired setting to enable Telnet or SNMP services Follow these steps to begin a management session using Local Console Management Step 1 Attach the serial cable to the RS 232 DB 9 or RJ 45 ...

Page 12: ...mmand Line Interface CLI of this Managed Switch is divided into three different modes After you enter the required username and password you start from the User mode The commands available depend on which mode you are currently in Enter a question mark at the system prompt to obtain a list of commands available for each command mode When you successfully access the Switch you begin in Root directo...

Page 13: ... While in User mode enter exit command Username Exit from current mode help While in User mode enter help command SWH Show available commands that can be used in User mode history While in User mode enter history command SWH List commands that have been used logout While in User mode enter logout command Username Logout ping While in User mode enter the ping command and followed by target IP SWH T...

Page 14: ...nter the console command SWH console Set up time out timer when the user is inactive disable While in Enable mode enter the disable command SWH Exit from current mode exit While in Enable mode enter the exit command SWH Exit from current mode help While in Enable mode enter the help command SWH Show available commands that can be used in Enable mode history While in Enable mode enter the history c...

Page 15: ...stem While in Enable mode enter the system command SWH system Configure the Managed Switch s basic information upgrade While in Enable mode enter the upgrade command SWH upgrade Upgrade the Managed Switch s firmware and restore the previous settings user While in Enable mode enter the user command SWH user Configure user accounts show While in Enable mode enter the show command or enter the show c...

Page 16: ... When in Config mode enter the igmp command SWH config igmp Configure IGMP settings mac When in Config mode enter the mac command SWH config mac Set up a static MAC table mirror When in Config mode enter the mirror command SWH config mirror Set up target port for mirroring multicast When in Config mode enter the multicast command SWH config multicast Set up multicasting groups mvr When in Config m...

Page 17: ... each listed command 2 3 2 Quick keys Using the key To do this Enter the commands Obtain a list of available commands in the current mode Enter incomplete characters then enter the question mark List all commands similar to incomplete characters Press the direction or key Scroll through the command history Enter unique part of a command and press TAB key The switch will automatically display the f...

Page 18: ...nt settings Show currently configured settings 2 3 3 1 Show command In this Managed Switch show command can be used in every mode that is useful and convenient for users to view displayed information without leaving the current mode By issuing the combination of show command and adequate parameters show command can provide different information for users not only to verify configurations and troub...

Page 19: ...ch M B Version This shows the motherboard version of this Managed Switch Date Code This shows the date code of this Managed Switch Up Time This shows how long this Managed Switch has been turned on since the last reboot Show available commands In User Enable and Configuration mode you can type show to view a list of commands available Show a Command s Current Settings In User Enable and Configurat...

Page 20: ...ombination of Show Command and In User Enable and Configuration mode you can type show and followed by the command listed above to view its current setting If there are sub commands within a command this is shown as the Managed Switch can also show sub commands available by issuing the show command and For example if you type show dot1x in User Enable Configuration mode then sub commands within Do...

Page 21: ...ng screen page appears Show Currently Configured Settings When you type a specific command in Enable or Config mode to configure or edit the setting of a certain function you can type show to view the setting you have just configured or edited For example when you are in SWH console and have changed the setting of time out function you can type show after SWH console then you can view the currentl...

Page 22: ...figured Users can type in commands or characters after the prompt 2 Command This column lists all commands that are available in the current mode 3 Purpose Description This column lists each command s purpose and description in the current mode 4 Usage This column lists each command s usage in the current mode 2 3 5 Usage Help When entering a command without the required parameter the system will ...

Page 23: ...on conventions are described below Conventions Descriptions Required parameters or values are in angle brackets Optional parameters or values are in square brackets port_list port_list allows you to enter several discontinuous port number separating by a comma for example port 5 7 9 12 or you can enter continuous port numbers with a hyphen and separating by a comma for example port 1 5 7 9 12 15 e...

Page 24: ...ot up message Enable Mode Password Enable mode is password protected When you try to enter Enable mode a password prompt will appear to request the user to provide the legitimate password Enable mode password is the same as the one entered after login password prompt By default no password is required Therefore press Enter key in password prompt Forget Your Login Username Password If you forget yo...

Page 25: ...an delete the default username admin account to prevent or restrict unauthorized access Boot up message Default username admin and without the password In SWH enter the question mark to show all commands available for User mode The screen shows as follows Command Purpose enable Enter the Enable mode exit Quit the User mode help Display a list of available commands in User mode history Display a li...

Page 26: ...e firmware and restore previous settings via TFTP or FTP user Set up a user account and its access privilege write Save running configurations to Flash 2 5 1 Backup command mode Enter the backup command in Enable mode Then the backup mode shows as follows SWH backup SWH backup Command Purpose Description Usage config Set Configuration config exit Exit from current mode exit SWH backup Prompt Comma...

Page 27: ...le mode Then the ip mode shows as follows SWH ip SWH ip Command Purpose Description Usage type Set Type type manual dhcp address Set IP Address address ip mask gw exit Exit from current mode exit show Show IP Settings show SWH ip Prompt Command Parameter Description type manual dhcp Specify whether the IP address is manually assigned or automatically assigned from the DCHP server When DHCP is spec...

Page 28: ...Switch are on the same network For example SWH ip address 192 110 1 2 255 255 255 0 120 110 1 5 exit Exit the current mode and return to Enable Mode show Show permanent MAC address and currently configured IP address subnet mask and gateway address of this Managed Switch 2 5 4 Ping command mode Ping is used to test the connectivity of end devices and also can be used to self test the network inter...

Page 29: ...he factory default settings Users can use the restore command in CLI user Web Management or simply press the Reset button located on the front panel to restore the device back to the initial state 2 5 6 Service command mode Enter the service command in Enable mode Then the service mode shows as follows SWH service SWH service Command Purpose Description Usage telnet Set Telnet telnet snmp Set SNMP...

Page 30: ...escription rdcommunity ip enable disable To enable or disable IP security If enabled the community may access the Managed Switch only through the management station which has the exact IP address specified in IP address field below If disabled the community can access the Managed Switch through any management stations For example SWH snmp community_community name ip enable ip_addr ip_addr Specify ...

Page 31: ...ode and return to SNMP service mode show Show detailed information of this community add trap_id trap_ip community To add a new trap destination This function will send traps to the specified destination trap_id 1 10 trap_ip The specific IP address of the network management system that will receive the trap community Enter the community name of up to 20 characters For example SWH snmp trap dest ad...

Page 32: ... enabled is set a trap notice will be sent when a certain situation occurs exit Quit the Trap mode and return to SNMP service mode SWH snmp trap mode show Show Trap mode information mode enable disable To enable or disable Web service on the Managed Switch For example SWH service web mode enable exit Quit the Web service mode and return to the service mode SWH service web show Show Web service inf...

Page 33: ...mand mode Enter the time server command in Enable mode Then the time server mode shows as follows SWH time server SWH time server Command Purpose Description Usage mode Set Mode mode enable disable ip addr Set IP Addr ip addr ip_addr 2nd addr Set 2nd Addr 2nd addr 2nd_addr syninterval Set Syn Interval syninterval hour time zone Set Time Zone time zone time_zone day saving Set Daylight Saving day s...

Page 34: ...Description firmware ftp tftp serverip username password filelocation To upgrade Firmware via FTP or TFTP serverip Enter the IP address of the FTP or TFTP server username Enter the username for Firmware upgrade via FTP password Enter the password for Firmware upgrade via FTP filelocation Enter the file location within the FTP or TFTP server Please refer to APPENDIX C for Firmware upgrade via TFTP ...

Page 35: ...nal This password is used to login to CLI and Enable mode administrator read_and_write read_only access_denied Four operation privileges are available in the Managed Switch Administrator Full access right includes maintaining user account and performing Firmware upgrade Read Write Full access right but cannot modify user account and perform Firmware upgrade Read Only Allow to retrieve information ...

Page 36: ... enable disable To enable or disable IP security function of this user account ip_addr ip_addr Enter the IP address for IP security function ip_addr Enter the IP address level administrator read_and_write read_only access_denied Set up the console level for this user account administrator read_and_write read_only access_denied Four operation privileges are available in the Managed Switch NOTE If y...

Page 37: ...ter Remarking Cmd Mode remarking stp Enter STP Cmd Mode stp security Enter Security Cmd Mode security switch Enter Switch Cmd Mode switch vlan Enter VLAN Cmd Mode vlan show Show current settings show SWH config Command Description acl Set up ACL configurations dot1x Set up RADIUS configurations exit Exit the config mode help Display a list of available commands in Configuration mode history Show c...

Page 38: ... be discarded add acl_id Add an ACL configuration rule 300 ACL rules can be created in this Managed Switch acl_id Specify an ACL ID from 1 to 300 NOTE Each ACL ID number can only be used once The lookup process will start from the ID with the lowest value to the highest one For example SWH config acl add 100 delete acl_id Delete an existing ACL configuration rule acl_id Specify an existing ACL ID ...

Page 39: ... rule any xx xx xx xx xx xx Specify any to denote all MAC addresses or type a specific source MAC address in AA AA AA AA AA AA format For example SWH config acl_100 source mac any dest mac any xx xx xx xx xx xx Set up which destination MAC address should apply to the rule any xx xx xx xx xx xx Specify any to denote all MAC addresses or type a specific destination MAC address in AA AA AA AA AA AA f...

Page 40: ...D function Disable Disable IPv6 MLD function source ip any x x x x y y y y Configure which source IP address applies to this rule any x x x x y y y y Specify any to denote any source IP addresses or specify a specific source IP address x x x x with a subnet mask y y y y For example SWH config acl_100 source ip any dest ip any x x x x y y y y Configure which destination IP address applies to this r...

Page 41: ...t numbers or specify a specific destination port number between 0 and 65535 For example SWH config acl_100 dest port 80 tcpflag any 0 255 Specify TCP Flag values any 0 255 Specify any to denote any values in TCP flag field or specify a specific TCP flag value service vid any 1 4094 Set up service provider VLAN ID This is used for double tagging any 1 4094 Specify any to denote any service provider...

Page 42: ...gress traffic When this is used you need to use newsvid 1 4094 parameter to indicate which new VID you would like to use For example SWH config_acl 100 permit type svid SWH config_acl 100 newsvid 200 Cvid Specify cvid to replace an original customer VID with a new one for egress traffic When this is used you need to use the following two parameters For example SWH config_acl 100 permit type cvid S...

Page 43: ...r VID to replace old one in egress traffic 1 4094 Specify a new customer VID reass queue enable disable Replace the customer priority or not enable disable Specify enable to replace with a new priority Specify disable to not replace with a new priority new queue 0 7 Specify a customer priority queue to replace an old one for egress traffic 0 7 Specify a new priority queue between 0 and 7 The prior...

Page 44: ... time 1 16 Specify the maximum numbers of authentication attempts between 1 and 16 For example SWH config dot1x sys maxquery 5 type port_list manual auto Set up the reauthentication type port_list Specify a port number or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 manual auto Specify manual to allow clients to re authenticate with the RADIUS server manually Specify auto to enable...

Page 45: ...P command mode Enter the igmp command in Configuration mode Then the igmp mode shows as follows SWH config igmp SWH config igmp Command Purpose Description Usage mode Set Mode mode enable disable router port Set Router Port router port port_list flooding Set Flooding vlanstate Set VLAN State vlanstate vid type vlanserver Set VLAN Server vlanserver vid ip maxresponse Set MAX Response Time maxrespon...

Page 46: ...time value between 0 and 255 seconds For example SWH config igmp maxresponse 100 fast leave enable disable When Fast Leave is enabled an interface will be removed immediately from the forwarding table entry as soon as the system detects an IGMP Leave message on that interface When disabled the system will wait for a period of time Max Response time before removing an interface exit Quit the curren...

Page 47: ...gment 2 to modify the details of the segment 2 add profile_name seg_id seg_id To create a new profile profile_name Specify a profile name of up to 20 characters seg_id Specify an existing segment ID The field for segment ID is from the entry registered in Segment option For Example SWH config profile add myprofile 2 3 4 5 6 delete profile_name To delete an existing profile profile_name Specify the...

Page 48: ... example SWH config igmpfilter state 1 4 10 15 18 19 enable filter port_list profile_name profile_name This allows the specified IP multicast profile information to pass through port_list Specify a port number or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 profile_name Specify an existing profile name The field for profile name is from the entry registered in Profile option For ex...

Page 49: ...naged Switch enter the forwarding port number 1 26 or specify filter or 27 to filter packets For 28 port Managed Switch enter the forwarding port number 1 28 or enter 29 to filter packets For example SWH config mac static delete xx xx xx xx xx xx 4094 24 SWH config mac static delete xx xx xx xx xx xx 4094 filter exit Quit the current mode and return to Configuration mode show Show current static s...

Page 50: ...mode Set Mode mode enable disable add Add MVR add vid receive source delete Delete MVR del vid group Enter Group Cmd Mode group exit Exit from current mode exit show Show MVR Settings show SWH config mvr Prompt Command Parameter Description mode enable disable To enable or disable MVR global settings For example SWH config mvr mode enable SWH config mvr add vlan_id rec_port_list sor_port_list serv...

Page 51: ...link ports resided in multicast VLAN and send and reecive multicast data are selected as source ports 1 26 or 1 28 Please note that the source ports specified here should be router ports as well Refer to IGMP command mode section for detailed explanations on setting up router ports serverip ip ip Specify the media server IP address exit Quit the current mode and return to Configuration mode SWH co...

Page 52: ...s multicast group The multicast IP address that can be specified ranges from 224 0 1 0 to 238 255 255 255 vlan_id Specify an existing VLAN ID for this entry port Specify a port number 1 26 or 1 28 to which multicast traffic will be forwarded For example SWH config multicast add 224 0 1 0 4094 24 delete ip addr vlan_id port Delete a multicast group ip addr Specify a multicast IP address for this mu...

Page 53: ... number separating by a comma for example port 5 7 9 12 or you can enter continuous port numbers with a dash and separating by a comma for example port 1 5 7 9 12 15 State Enable or disable the current port state Type Specify copper or fiber as the preferred media type Port Type Select Auto Negotiation or Manual mode as the port type Speed When you select Manual port type you can further specify t...

Page 54: ... queue rate limit Enter Rate Limit Cmd Mode rate limit exit Exit from current mode exit show Show QoS Settings show SWH config qos Prompt Command Parameter Description class port_list queue Configure the default class for each port port_list Specify a port number or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 queue 0 7 For example SWH config qos class 1 5 10 4 mode port_list weigh...

Page 55: ...rmat 5 7 8 9 12 or 5 7 9 12 bit_rate Ingress bit rate for port 1 24 is from 128 to 100000KBits Sec and from 128 to 1000000 KBits Sec for port 25 and 26 or port 25 28 Indicating 0 is to disable ingress rate limit For example SWH config qos rate limit ingress 3 6 15 20 1500 SWH config qos rate limit egress port_list bit_rate To specify egress bit rate of the selected ports port_list Specify a port n...

Page 56: ...le port numbers with the format 5 7 8 9 12 or 5 7 9 12 enable disable To enable or disable DSCP of the selected ports For example SWH config remarking dscp 1 5 10 13 enable SWH config remarking 802 1p port_list enable disable To enable or disable 802 1p on the port port_list Specify a port number or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 enable disable To enable or disable 80...

Page 57: ... is associated with a port number in the STP code By default every switch s system priority is 32768 You can change the value by selecting from the pull down menu but only in increments of 4096 The Managed Switch with the lowest priority will be selected as the root bridge which is the central bridge in the spanning tree If switches have the same priority the other BID component MAC address become...

Page 58: ...u choose STP you can not enable ports to be edge ports or point to point ports The fields for Edge and Point to point become selectable in RSTP Physical Port Settings when you select RSTP For example SWH config stp sys version stp exit Quit the current mode and return to STP mode show Show currently configured STP settings state port_list enable disable To enable or disable each port s RSTP or STP...

Page 59: ...Specify a port number or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 For example SWH config stp edge 1 4 10 15 18 19 enable NOTE1 For each port the fields for Edge and Point to point can not be enabled at the same time In other words when the port s Edge is enabled Point to point must be set to disabled NOTE2 If you choose STP as the current running version you can not enable port...

Page 60: ...tings show SWH config ska Prompt Command Parameter Description mode enable disable To enable or disable DHCP Opt 82 Relay Agent Global setting port port_list port_list Specify a port number or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 For example SWH config security opt82 port 1 4 10 15 18 19 SWH config security opt82 trust port port_list When Trust Port is set to enabled a it w...

Page 61: ...enable or disable snooping initiated number To specify time that packets might be received number 0 9999 Seconds For example SWH config security snooping initiated 4 leased number To specify expired time of packets number 180 259200 Second For example SWH config security snooping leased 86400 exit Quit the current mode and return to Security Configuration mode SWH config security snooping show Sho...

Page 62: ... CZ T 420 533 338 854 l F 420 533 338 883 l www signamax eu 61 mask Specify a subnet mask vlan_ip 1 4094 port 1 24 exit Quit the current mode and return to Security Configuration mode show Show or verify currently configured Static IP settings ...

Page 63: ...g security storm multicast 5000 exit Quit the current mode and return to Security Configuration mode SWH config security storm show Show or verify currently configured Storm Control settings polling int sec Specify a time interval for how often the Managed Switch checks or refresh broadcast traffic sec 3 300 seconds For example SWH config anti bcast polling int 9 threshold port_list packet_rate Sp...

Page 64: ...ter the switch command in Config mode Then the switch mode shows as follows SWH config switch SWH config switch Command Purpose Description Usage max frame Set Max Frame Size max frame num exit Exit from current mode exit show Show Switch Settings show SWH config switch Prompt Command Parameter Description SWH config switch max frame num Specify the maximum frame size num Specify 0 to denote 1522 ...

Page 65: ... mode enable disable To enable or disable VLAN Global mode filter enable disable To enable or disable ingress filter When enabled ingress traffic that belongs to one of the existing VID entries is allowed to pass through otherwise they will be dropped before checking the entire VID table When disabled ingress traffic will be checked against all existing VID entries before allowing them to pass thr...

Page 66: ...ow or verify currently added or deleted VLANs Edit details of a dot1q VLAN entry If you would like to modify an existing VLAN entry you can enter dot1q VID after SWH config vlan For example enter SWH config vlan dot1q 9 to modify the details of VLAN 9 entry port list port_list port_list Specify a port number or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 name name name Specify a n...

Page 67: ...Show or verify currently added or deleted service VLANs add id port ether type vid Protocol VLANs allow users to divide traffic into VLANs based on the required protocol When a frame is received on a port that is configured as protocol based VLAN its membership can be determined according to the protocol of the inbound frame id 1 64 port Specify a port number 1 26 or 1 28 ether type Specify the pr...

Page 68: ...ber or multiple port numbers with the format 5 7 8 9 12 or 5 7 9 12 cpu_vid Specify a VID to CPU between 1 and 4094 tag untag Specify ingress traffic from the management port is tagged or untagged For example SWH config vlan mgt vlan 1 4 10 15 18 19 4090 tag pvid port_list pvid The range of PVID is between 1 and 4094 VLAN ID will be assigned to untagged frames received on the interface The default...

Page 69: ...fic will be based on VLAN table settings Specifying un modify when you would like egress traffic to stay intact In other words frames that are tagged will stay tagged frames that are untagged will stay untagged For example SWH config vlan egress 1 4 10 15 18 19 un_modify exit Quit the current mode and return to Configuration mode show Show or verify VLAN configurations ...

Page 70: ...ged devices NMS provide the bulk of the processing and memory resources required for the complete network management SNMP Manager often composed by desktop computer work station and software program such like HP OpenView Totally 4 types of operations are used between SNMP Agent Manager to change the MIB information These 4 operations all use the UDP IP protocol to exchange packets GET This command...

Page 71: ...e later in its Network Management menu Follow these steps to manage the Managed Switch through a Web browser Use the RS 232 DB 9 console port or one of the 10 100Base TX RJ 45 ports as the temporary RJ 45 Management console port to set up the assigned IP parameters of the Managed Switch including IP address Subnet Mask and Default Gateway of the Managed Switch if required Run a Web browser and spe...

Page 72: ...witch port configuration VLAN configuration and other functions 4 Switch Monitor View the operation status and traffic statistics of the ports 5 System Utility Firmware Upgrade Load Factory Settings etc 6 Save Configuration Save all changes to the system 7 Reset System Reset the Managed Switch 4 1 Information Click the Information folder and the following sub items appear 1 System Information Chan...

Page 73: ...identify the Managed Switch in relation to your network for example Backbone 1 This name is mainly used for reference only System Location Enter a brief description of the Managed Switch location up to 55 alphanumeric characters Like the name the location is for reference only for example 13th Floor Model Name View only field that shows the product s model name Firmware Version View only field tha...

Page 74: ...bled the login account can only access the Managed Switch via the specified IP address IP Address Enter the specific IP address that is used for IP security function When IP security is enabled the user account tries to login from the authorized specified IP address will be granted the access Console Level Select the desired privilege for the console operation from the pull down menu Four operatio...

Page 75: ...Default Account s console level to Access Denied so that users are no longer able to login using this default username account 4 2 Network Management In order to enable network management of the Managed Switch proper network configurations are required To do this click Network Management folder from the Main menu and then the following sub items appear 1 Network Configuration Set up the required I...

Page 76: ... configuration image from the server For information about how to set up a DHCP server please refer to APPENDIX A IP Address Enter the unique IP address of this Managed Switch You can use the default IP address or specify a new one when the situation of address duplication occurs or the address does not match up with your network The factory default setting is 192 168 0 1 Subnet Mask Specify the s...

Page 77: ...change its setting Console Time Out Specify the desired time that the Managed Switch will wait before disconnecting an inactive console telnet session Specifying 0 means an inactive connection will never be disconnected When you use a web browser such as IE Explorer to manage the switch the timeout time is set to approximately 5 minutes In other words when you are inactive for about 5 minutes you ...

Page 78: ...automatically connect to the second time server Synchronization Interval The time interval to synchronize from NTP time server Time Zone Select the appropriate time zone from the pull down menu Daylight Saving Time To enable or disable the daylight saving time function It is a way of getting more daytime hour s by setting the time to be hour s ahead in the morning Daylight Saving Time Offset Click...

Page 79: ... alphanumeric characters This is mainly for reference only SNMP Level Click the pull down menu to select the desired privilege for the SNMP operation Administrator Full access right includes maintaining user account and performing Firmware upgrade Read Write Full access right but cannot modify user account and perform Firmware upgrade Read Only Allow to retrieve information only Access Denied Comp...

Page 80: ... of sending trap to the specified destination Destination Enter the specific IP address of the network management system that will receive the trap Community Enter the community name of the network management system Click the Change button to modify each trap destination s settings and the new settings will appear in the SNMP Trap Destination table below Click the Delete button to clear each trap ...

Page 81: ...cast Configuration To create edit or delete Static Multicast table 6 Rapid Spanning Tree Set up RSTP switch settings aggregated port settings physical port settings etc 7 802 1X Configuration Set up the 802 1X system port Admin state port reauthenticate 8 MAC Address Management Set up static MAC address table 9 VLAN Configuration Set up VLAN mode and VLAN configuration 10 QoS Configuration Set up ...

Page 82: ...tion Port Configuration from the Switch Management menu and then the following screen page appears Click the Edit button on the port that you would like to modify Click the Change button after you set up new configurations Newly configured settings will appear in the table below Port Number View only field that shows the port number that you would like to edit Port Media Select copper or fiber as ...

Page 83: ...t Mirroring allows users to monitor Source ports traffic flows To set up Target Port to mirror Source Port select the option Port Mirroring from the Switch Management menu and then the following screen page appears Source Port Tick the checkbox if you would like to enable Target Port s mirroring on Source port s Both ingress incoming and egress outgoing traffic will be copied to the target port Ta...

Page 84: ... 5 Static Multicast Configuration Select the option Static Multicast Configuration from the Switch Management menu and then the following screen page appears IP Address Specify the destination IP address The multicast IP address that can be specified ranges from 224 0 1 0 to 238 255 255 255 VLAN Specify the VLAN where the packets with the Destination MAC address can be forwarded Forwarding Port If...

Page 85: ... bandwidth Spanning tree allows a network design to include spare redundant links to provide automatic backup paths if an active link fails without the danger of bridge loops or the need for manually enabling or disabling these backup links To provide faster spanning tree convergence after a topology change an evolution of the Spanning Tree Protocol Rapid Spanning Tree Protocol RSTP is introduced ...

Page 86: ...the length of time that a port saves BPDU configuration information By default the maximum age is set to 20 seconds Hello Time Periodically a hello packet is sent out to all ports that are not in blocking mode to communicate information about the topology throughout the entire Bridged Local Area Network The default hello time is 2 seconds but can be adjusted between 1 and 10 seconds Forward Delay ...

Page 87: ...and interfaces then you may need to adjust the priorities to achieve optimized performance Priority Select each port s priority Edge Edge ports are determined by their locations and are connected to end devices such as hosts If you want ports to be edge ports set them to enable The default setting to all ports is disabled and will not receive BPDU Point to Point If the port link is connected to an...

Page 88: ...rwise the clients will not be granted access to LAN Once clients successfully authenticate with the authentication server all ingress and egress traffic from clients can pass through the port Click the folder 802 1X Configuration from the Switch Management menu and then three options within this folder will be displayed as follows 1 802 1X System Set up 802 1X server IP secret re authentication pe...

Page 89: ...the switch When the authentication attempts reach the specified number and all fail the authentication server will not allow users to authenticate for a period of time Reauth Period Specify the time value between 10 and 3600 seconds This is used to set up how often a client is able to re authenticate with the RADIUS server after they reach the max query attempts EAP Timeout Specify the time value ...

Page 90: ... the authentication server 4 3 7 3 802 1X Port Reauthenticate Select the option 802 1X Port Reauthenticate from the 802 1X Configuration menu and then the following screen page appears Reset Tick the checkbox on ports that you would like them to authenticate with the server The authentication message will be sent immediately after you click the Submit button 4 3 8 MAC Address Management Select the...

Page 91: ...AN can enhance performance by conserving bandwidth and improve security by limiting traffic to specific domains A VLAN is a collection of end nodes grouped by logics instead of physical locations End nodes that frequently communicate with each other are assigned to the same VLAN no matter where they are physically located on the network Another benefit of VLAN is that you can change the network to...

Page 92: ...ilter To enable or disable ingress filter When enabled ingress traffic from a certain port that is a member port of a VLAN will be forwarded to other member ports in the same VLAN otherwise they will be dropped ingress traffic from a VLAN is not a member port of that VLAN When disabled ingress traffic will be forwarded to other member ports that are in the same VLAN See below for an example Ingres...

Page 93: ...rwarding Table Click the Edit button on the port that you would like to modify Click the Change button to apply the new settings and save them in the Switch s run time memory after configurations are set up Please note that before you logout from the Managed Switch you have to save configurations otherwise all changes will not be saved to Flash Port Number This field shows the port number that you...

Page 94: ...tween 1 and 4094 Server Port Tick the checkbox if you would like the port to become a server port 4 3 9 2 802 1q Tag VLAN Member Select the option 802 1q Tag VLAN Member from the VLAN Configuration menu and then the following screen page appears This Managed Switch supports up to 128 sets of VLANs Name Enter a descriptive name up to 15 characters for this 802 1q VLAN entry VID Specify a VID for th...

Page 95: ...l VLAN Protocol VLANs allow users to divide traffic into VLANs based on the required protocol When a frame is received on a port that is configured as protocol based VLAN its membership can be determined according to the protocol of the inbound frame When a frame is without a tag the Managed Switch will check settings in Protocol VLAN table first If there are no settings in Protocol VLAN table the...

Page 96: ...apply the settings Please note that before you logout from the Managed Switch you have to save configurations otherwise all changes will not be saved to Flash 4 3 9 6 Port based VLAN Select the option Port based VLAN from the VLAN Configuration menu and then the following screen page appears Port based VLAN Mode Enable or disable Port based VLAN function By default 26 sets of port based VLANs can ...

Page 97: ... various grades of network service to different types of traffic such as multi media video protocol specific time critical and file backup traffic Click the QoS Priority folder and then the following sub items appear 1 QoS Port Configuration To set up each port s QoS default class queuing mode and Queue Weighted 2 QoS Mapping Configuration To create edit or delete QCL settings 3 Rate Limiters To c...

Page 98: ...res bandwidth at egress ports by using scheduling weights 1 2 4 8 for queue 1 through 4 respectively Weight Q0 Q7 Specify a weight value to each queue Q0 Q7 4 3 10 2 QoS Mapping Configuration Select the option QoS Mapping Configuration from the QoS Priority menu and then the following screen page appears 802 1p Mapping to Queue Queue Set up 802 1p and queue mapping The value allowed is between 0 a...

Page 99: ...g to IGMP traffic IGMP snooping as implied by the name is a feature that allows the switch to listen in on the IGMP conversation between hosts and routers by processing the layer 3 packets that IGMP packets sent in a multicast network When IGMP snooping is enabled in a switch it analyses all the IGMP packets between hosts connected to the switch and multicast routers in the network When a switch r...

Page 100: ...r disable IGMP filter and configure each port s IGMP filter 4 3 11 1 IGMP Configuration Select the option IGMP Configuration from the IGMP Snooping menu and then the following screen page appears IGMP Mode Enable or disable IGMP Global mode Max Response Time Specify a time value between 0 and 255 seconds The Max Response Time is used to specify the maximum allowed time before sending a responding ...

Page 101: ... the existing VLAN entry s descriptions VID View only field that shows the existing VLAN IDs Snooping Enable or disable IGMP snooping function Server IP Enter the server IP address 4 3 11 3 IPMC Segment Select the option IPMC Segment from the IGMP Snooping menu and then the following screen page appears ID Specify an ID number between 1 and 400 Segment Name Enter a descriptive name for this segmen...

Page 102: ...PMC Profile Select the option IPMC Profile from the IGMP Snooping menu and then the following screen page appears Profile Name Enter a descriptive name for this profile Up to 20 characters are allowed Segment Enter the existing segment IDs for this profile Click Insert to add this rule in the IPMC profile table below ...

Page 103: ...eld shows the port number that you would like to edit Channel Limit Specify the maximum transport multicast channels that can be received The channel value allowed is between 1 and 128 State Enable or disable each port s IPMC Profile Enter the IPMC profile names The fields for profile names are case sensitive Please enter the exact profile names as registered 4 3 12 MVR Configuration MVR stands fo...

Page 104: ...receive port Optional Limitation Receiver ports on a switch can be in different VLANs but they should not belong to the multicast VLAN Do not configure MVR on private VLAN ports MVR can coexist with IGMP snooping on a switch MVR data received on an MVR receiver port is not forwarded to MVR source ports MVR does not support IGMPv3 messages MVR on IPv6 multicast groups is not supported Click the fol...

Page 105: ...tton to make your setting effective MVR VLAN Table VID View only field that shows the specified MVR VLAN ID for current configuration Click the Insert button to register a new MVR VLAN ID and then the following screen page appears VLAN ID Specify a VLAN ID for multicast VLAN Sever IP Address Specify the media server IP address Port State There are three port states for selection Not included in th...

Page 106: ... Click the Insert button to add the entry to MVR Group Table 4 3 13 Security Configuration SKA refers to Secure Customer Connections In this menu it provides DHCP snooping DHCP option 82 DHCP layer 2 relay and customer port Port number 1 24 filtering functions DHCP Option 82 Guidelines The Managed Switch can add information about the source of client DHCP requests that relay to DHCP server by addi...

Page 107: ...tion 2 DHCP Port Settings Customer port Port 1 24 DHCP snooping setting 3 Filter Configuration Customer port Port 1 24 filtering setting 4 Static IP Table Configuration To create static IP table for DHCP snooping setting 5 Storm Control Enable or disable unknown unicast and multicast control by port and set up threshold packet per second 6 Anti broadcast Control Enable or disable anti broadcast co...

Page 108: ...ick the checkbox on ports that you would like them to become trust ports The trusted ports will not discard DHCP messages For example A DHCP request is from Port 1 that is marked as both Opt 82 port and trust port A If a DHCP request is with Opt 82 Agent information and then the Managed Switch will forward it B If a DHCP request is without Opt82 Agent information and then the Managed Switch will a...

Page 109: ...on Select the option Filter Configuration from the Security Configuration menu and then the following screen page appears Snooping Mode Enable or disable DHCP Snooping on the Managed Switch NOTE The connection between the Managed Switch and DHCP server can only be made via uplink ports port 25 26 or port 25 28 Initiated Time Specify the time value 0 9999 Seconds that packets might be received Leas...

Page 110: ...SIGNAMAX a s Office Vlarska 22 627 00 Brno CZ T 420 533 338 854 l F 420 533 338 883 l www signamax eu 109 UPnP Filter Enable or disable UPnP filter ...

Page 111: ... clients to the Managed Switch After you complete Step 1 2 connect your clients to the Managed Switch Your clients will send a DHCP Request out to DHCP Server soon after they receive a DHCP offer When DCHP Server responds with a DHCP ACK message that contains lease duration and other configuration information the IP configuration process is complete If you connect clients to the Managed Switch bef...

Page 112: ...ugh Click Insert to add this entry to Static IP Table Click Edit to modify the settings of the selected entry Click Delete to remove the selected entry from the Static IP Table 4 3 13 6 Storm Control Select the option Storm Control from the Security Configuration menu and then the following screen page appears Unknown Unicast To set up each port s unknown unicast packet rate Allowable unicast pack...

Page 113: ...default the polling interval is 3 seconds Broadcast To set up each port s broadcast packet rate per second The packet rate for port 1through 24 is 0 148810 The packet rate for port 25 26 or 25 28 is 0 1048575 State Enable or disable anti broadcast function by port 4 3 14 Access Control List Management Click the folder Access Control List Management from the Switch Management menu and then three op...

Page 114: ...entry that you would like to modify ID The total of 128 entries can be configured Rate Specify the rate for each rate limiting entry Click the Change button to save your new settings in the Rate Limiter Table below 4 3 14 2 ACL Configuration Select the option ACL Configuration from the Access Control List Management menu and then the following screen page appears Click the Apply ACL Rule button to...

Page 115: ...ails of each ACL rule Click the Insert button to add a new ACL rule Click the Edit button on the entry that you would like to modify and then click the Change button to enter the editing screen page Click the Delete button to remove the entry from the ACL Rule Table Rule ID Specify an ACL ID 1 300 for this rule Each ID can only be used once ...

Page 116: ... AA AA AA AA AA format Ether Type Select Any to denote any Ethernet types or specify Ethernet type value in hexadecimal notation VID Select Any to denote traffic from any VLAN or specify an existing VID to denote source traffic from the specified VLAN TCP UDP Source Port Select Any to denote any TCP UDP source port numbers apply or specify a specific source port number between 0 and 65535 TCP UDP ...

Page 117: ...n IPv6 to handle real time applications with sequences Select Any to denote any flow label values or specify a specify flow label value between 0 and 1048575 Protocol Next Header Specify the IP protocol to be used Select any denote any protocols or specify the type of transport packets used e g 1 ICMP 6 TCP 17 UDP TOS Specify TOS Type of Service priority level Select any to denote any priority lev...

Page 118: ... discard the packets Redirect Select redirect to route packets to the specific port If you want to use Redirect you need to set up a redirect port Copy to CPU Select Copy to CPU to send a copy of packets to CPU Redirect Port Select a redirect port Logging Specify a logging ID that applies to this ACL rule Rate Limit Specify the rate limiting ID that applies to this ACL rule New Service VID Specify...

Page 119: ...the DHCP learning table 4 MAC Address Table List current MAC address learned by the Managed Switch 5 Port Counters View port traffic statistics port packet error statistics and port packet analysis statistics 6 RSTP Monitor View RSTP VLAN Bridge Port Status and statistics 7 IGMP Monitor View IGMP status and Groups table 8 SFP Information View the current port s SFP information e g speed Vendor ID ...

Page 120: ...f Bridged LAN Learning A port in this state prepares to participate in frame relay Frame relay is temporarily disabled in order to prevent temporary loops which may occur in a Bridged LAN during the lifetime of this state as the active topology of the Bridged LAN changes Learning is enabled to allow information to be acquired prior to frame relay in order to reduce the number of frames that are un...

Page 121: ... are all dropped 4 4 3 DHCP Snooping Select the option DHCP Snooping from the Switch Monitor menu and then the following screen page appears Client Port View only field that shows where the DHCP client binding port is Server Port View only field that shows DHCP server port number VID View only field that shows the VLAN ID of the client port Client IP Address View only field that shows the client s...

Page 122: ...reset MAC addresses will be cleared Click the Update button to refresh the MAC Address Table Click the Clear button to remove all MAC addresses learned from the table 4 4 5 Port Counters Click Port Counters folder from the Switch Monitor menu and then the following sub items appear 1 Port Traffic Statistics View each port s received or sent frames and bytes 2 Port Packet Error Statistics View each...

Page 123: ...ved from each port Frames Received View only field that show the total frames received from each port Bytes Sent View only field that show the total bytes sent from each port Frames Sent View only field that show he total frames sent from each port Total Bytes View only field that show the total bytes received and sent from each port 4 4 5 2 Port Packet Error Statistics Port Packet Error Statistic...

Page 124: ...rrors received RX Undersize View only field that show undersized frames received RX Oversize View only field that show oversized frames received RX Fragments View only field that show fragment frames received RX Jabber Frames View only field that show Jabber frames received TX Dropped View only field that show dropped frames sent TX CRC Alignment View only field that show CRC Alignment error frame...

Page 125: ...eld that show how many frames in 65 127 bytes received RX Frames 128 255 Bytes View only field that show how many frames in 128 255 bytes received RX Frames 256 511 Bytes View only field that show how many frames in 256 511 bytes received RX Frames 512 1023 Bytes View only field that show how many frames in 512 1023 bytes received RX Frames 1024 MAX Bytes View only field that show how many frames ...

Page 126: ...tion and max age and hello time 2 RSTP Port Status This shows the Managed Switch s RSTP status 4 4 6 1 RSTP VLAN Bridge Overview RSTP VLAN Bridge Overview allows users to view a list of all RSTP VLANs brief information such as VLAN ID Bridge ID topology status and Root ID Select RSTP VLAN Bridge Overview from the RSTP Monitor menu and then the following screen page appears In this page you can fin...

Page 127: ...w only field that shows forward delay time of the Managed Switch in a specific VLAN Root ID View only field that shows the Root Bridge s ID 4096 is the Root Bridge s priority 00 06 19 09 33 12 is the Root Bridge s MAC address 4 4 6 2 RSTP Port Status RSTP Port Status allows users to view a list of all RSTP ports information Select RSTP Port Status from the RSTP Monitor menu and then the following ...

Page 128: ... a list of IGMP queries information in VLAN s such as VLAN ID Querier and Queries Transmitted Received packets Select IGMP Snooping Status from the IGMP Monitor menu and then the following screen page appears VLAN ID VID of the specific VLAN The IGMP querier periodically sends IGMP general queries to all hosts and routers 224 0 0 1 on the local subnet to find out whether active multicast group mem...

Page 129: ...Table from the IGMP monitor menu and then the following screen page appears VID VID of the specific VLAN Group The multicast IP address of IGMP querier Port The port s grouped in the specific multicast group 4 4 8 SFP Information This menu provides users detailed information about SFP plugged in Port 25 and Port 26 Click SFP Information menu and then the following sub items appear 1 SFP Port Info ...

Page 130: ...ver Vendor Name View only field that shows the vendor name of the slide in SFP transceiver Vendor PN View only field that shows the vendor PN of the slide in SFP transceiver Vendor SN View only field that shows the vendor SN of the slide in SFP transceiver 4 4 8 2 SFP Port State Select SFP Port Info from the SFP Information menu and then the following screen page appears Temperature C View only fi...

Page 131: ...ding on whether a client connects to a 802 1X enabled port or not Authorizing means that a client connects to a 802 1x enabled port whereas Linkdown means that no client connects to a 802 1x enabled port On the other hand when Port Admin State is disabled the state information displayed here will show Disabled For further information on how to set up Port Admin State please refer to 802 1X Configu...

Page 132: ...ddress User Name Enter the specific username to access the File Server For FTP only If you choose TFTP as your protocol leave this field blank Password Enter the specific password to access the File Server For FTP only If you choose TFTP as your protocol leave this field blank File Location Enter the specific path and filename within the File Server Click the Upgrade button to perform firmware upg...

Page 133: ...s field blank Password Enter the specific password to access the File Server For FTP only If you choose TFTP as your protocol leave this field blank File Location Enter the specific path and filename within the File Server Backup Perform configuration backup Restore Reload the previously created configuration file NOTE There are three ways to set the Managed Switch back to the factory default sett...

Page 134: ...aged Switch s configurations back to factory defaults Except Network Settings Click the Load button to return the Managed Switch s configurations back to factory defaults except network configurations IP address mask default gateway address 4 6 Save Configuration Click the Save button to save running configurations to flash 4 7 Reset System Click the Reset button to restart the Managed Switch Plea...

Page 135: ...or auto upgrade of firmware and configuration please make sure the Managed Switch that you purchased can support DHCP Auto provisioning Setup procedures and auto provisioning process are described below for your reference A Setup Procedures Step 1 Setup Environment DHCP Auto provisioning enabled products that you purchased support the DHCP option 60 to work as a DHCP client The system includes ISC...

Page 136: ...x eu 135 Step 2 Prepare dhcpd conf file You can find this file in Linux ISC DHCP server usr local etc dhcpd conf Step 3 Copy the marked text to dhcpd conf A sample of dhcp text is provided in APPENDIX B Please copy the marked area to dhcpd conf file Sample dhcp text Copy the text to dhcpd conf file ...

Page 137: ...1 FTP Protocol 0 TFTP 3 Specify the FTP or TFTP IP address 4 Login FTP server anonymously 5 Specify FTP Server login name 6 Specify FTP Server login password 7 Specify the product model name 8 Specify the firmware filename 9 Specify the MD5 for firmware image The format of MD5 might be the same as the one in the sample text 10 Specify the configuration image filename 11 Specify the MD5 for configu...

Page 138: ...nce to be equal to DHCP when provisioning and it results in MD5 never match and causes the device to reboot endless In order for your Managed Switch to retrieve the correct configuration image in TFTP FTP Server please make sure the filename of your configuration file is defined exactly the same as the one specified in in dhcpd conf For example if the configuration image s filename specified in dh...

Page 139: ...r will tell the device how to get a new firmware or configuration 2 The device will compare the firmware and configuration MD5 code form of DHCP option every time when it communicates with DHCP server 3 If MD5 code is different the device will then upgrade the firmware or configuration However it will not be activated right after 4 If the Urgency Bit is set the device will be reset to activate the...

Page 140: ...ow to your dhcpd conf file ext below to your dhcpd conf file option space CTS protocol 0 tftp 1 ftp option CTS protocol code 1 unsigned integer 8 option CTS server ip code 2 ip address option CTS server login name code 3 text option CTS server login password code 4 text option CTS firmware file name code 5 text option CTS firmware md5 code 6 string option CTS configuration file name code 7 text op...

Page 141: ...8 854 l F 420 533 338 883 l www signamax eu 140 option CTS firmware md5 d8 e2 f0 de 7d a5 8e 2c 6e 4e a7 5a 39 78 07 d8 option CTS configuration file name metafile option CTS configuration md5 95 d6 5c 39 4d 83 76 30 61 16 9b de 37 ba 12 84 option CTS option 1 ...

Page 142: ... your PC Figure1 Open the TFTP Server Click Browse to change the base directory to the folder where the new Firmware is located Please note that the file such as 500 7624FE2GC_FW_1 02 1A_101203 bin for Firmware upgrading must be in the directory that you locate otherwise Firmware upgrading will fail 192 168 0 15 shown in the next figure is the IP address for TFTP server When upgrading Firmware you...

Page 143: ... well It must belong to 192 168 0 0 24 network domain for example 192 168 0 15 Step 3 Setup the Upgrade Configuration Use the following commands to update Firmware Username admin Password SWH enable Password SWH upgrade SWH upgrade firmware tftp 192 168 0 15 500 7624FE2GC_FW_1 02 1A_101203 bin In the preceding example 192 168 0 15 is the IP address for TFTP server 500 7624FE2GC_FW_1 02 1A_101203 b...

Page 144: ...SIGNAMAX a s Office Vlarska 22 627 00 Brno CZ T 420 533 338 854 l F 420 533 338 883 l www signamax eu 143 This page is intentionally left blank ...

Reviews: